NEW258936
Left shift of negative value in JSC::RegisterAtOffset::offset()
https://bugs.webkit.org/show_bug.cgi?id=258936
Summary Left shift of negative value in JSC::RegisterAtOffset::offset()
Xi Ruoyao
Reported 2023-07-06 09:52:18 PDT
JSC::RegisterAtOffset::m_offsetBits is ptrdiff_t, so it's signed. And on most platforms the stack grows downward, so the value if often negative. The C++ standard explicit deems left shift of negative value undefined.
Attachments
Xi Ruoyao
Comment 1 2023-07-06 11:26:37 PDT
Radar WebKit Bug Importer
Comment 2 2023-07-13 09:53:18 PDT
Note You need to log in before you can comment on or make changes to this bug.